CVE-2019-2987 is a difficult-to-exploit vulnerability in the 2D component of Oracle Java SE versions 11.0.4 and 13, also affecting Debian, NetApp, and Red Hat products. An unauthenticated attacker with network access can cause a partial denial of service. This primarily impacts Java deployments running untrusted code within a sandbox. The vulnerability has a low CVSS v3.0 base score of 3.7, indicating a low availability impact. Its attack complexity is high, and no user interaction is required for exploitation. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. It is not listed in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0.4CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:11.0.4:*:*:*:*:*:*:* | ||
13.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:13.0.0:*:*:*:*:*:*:* | ||
11.0.4CPE matchmatch criteria | cpe:2.3:a:oracle:jre:11.0.4:*:*:*:*:*:*:* | ||
13.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:13.0.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.